Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

1570 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.1)0.22%—Openshift Pipelines OperatorAITektonAIKueueAICert-managerAI4/6/20266/9/2026
A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any…
AnalizadaCrítica (9.8)0.55%—Oracle Hospitality Opera 5 Property Services28/5/202617/6/2026
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6 and 5.6.28. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
AnalizadaAlta (7.8)0.18%—IBM Operations Analytics LOG Analysis27/5/202617/6/2026
IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.
Pendiente de análisisMedia (5.1)0.13%—IBM MQAIIBM MQ OperatorAI27/5/202617/6/2026
IBM MQ Operator SC2: v3.2.0 through 3.2.23CD: v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 - v3.7.2, v3.8.0, v3.8.1, v3.9.0, v3.9.1LTS: v2.0.0 - 2.0.29 and IBM supplied MQ Advanced container images SC2: 9.4.0.6 through r1, 9.4.0.6-r2, 9.4.0.7-r1, 9.4.0.10-r1, 9.4.0.10-r2, 9.4.0.11-r1,…
AnalizadaCrítica (9.8)0.36%—IBM Operations Analytics LOG Analysis27/5/202617/6/2026
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default, which makes it easier for attackers to…
ModificadaMedia (6.5)0.49%💥 PoCApache Flink Kubernetes Operator26/5/202624/7/2026
Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses. This lets a user with CR create permissions read files from the operator…
AplazadaMedia (5.5)0.72%—Acrel Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI26/5/202623/7/2026
A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionality of the file /SubstationWEBV2/app/..;/main/upfile. Executing a manipulation of the argument path can lead to path traversal. The attack may be…
Pendiente de análisisAlta (8.7)0.32%—Ppt30 Operating SystemAI26/5/202624/7/2026
An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may be used by an unauthenticated network-based attacker to permanently prevent legitimate users from interacting with the service.
AplazadaMedia (5.5)0.41%—Acrel Eems Enterprise Power Operation AND Maintenance Cloud Platform 3000webv2AI26/5/202623/7/2026
A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2. Affected by this vulnerability is an unknown functionality of the file /SubstationWEBV2/app/..;/calc/getCalcmeterDetailDayListTree. Performing a manipulation of the argument sort results in sql…
AplazadaAlta (7.1)0.22%—Digital Operations Services INC WifiburadaAI21/5/202623/7/2026
Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass. This issue affects WifiBurada: through 21052026. NOTE: The vendor was contacted early about this disclosure but did not…
AnalizadaAlta (8.8)0.22%—Veritas Infoscale Operations Manager20/5/202623/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge.
AnalizadaMedia (5.4)0.24%—Veritas Infoscale Operations Manager20/5/202623/7/2026
InfoScale VIOM 9.1.3 allows XSS.
AnalizadaMedia (6.5)0.35%—Veritas Infoscale Operations Manager20/5/202623/7/2026
SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.
AplazadaMedia (4.9)0.26%—External-secrets External Secrets OperatorAI11/5/202617/6/2026
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.1, a user who only has permission to create ExternalSecret resources can cause the operator to create a Secret that Kubernetes will automatically populate with a long-lived…
AplazadaMedia (5.3)0.37%—External-secrets External Secrets OperatorAI11/5/202617/6/2026
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.0, Namespaced SecretStore resources that used CAProvider with type ConfigMap could resolve CA material from another namespace when caProvider.namespace was set. This bypassed…
AplazadaBaja (2)0.33%—Amtt Hotel Broadband Operation SystemAI3/5/202617/6/2026
A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected is an unknown function of the file /manager/card/cardhand_submit.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be…
AplazadaBaja (2.1)0.38%—Acrel Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI3/5/202617/6/2026
A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. The manipulation of the argument File results in unrestricted upload. The attack may be launched remotely. The exploit…
AplazadaMedia (5.5)0.41%—Acrel Electrical Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI3/5/202617/6/2026
A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. The manipulation of the argument fCircuitids leads to sql injection. The attack may be initiated remotely. The…
AplazadaMedia (5.5)0.59%—Browseroperator Browser-operator-coreAI28/4/202617/6/2026
A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith of the file scripts/component_server/server.js. Executing a manipulation of the argument request.url can lead to path traversal. The attack can be launched remotely. The exploit has been made…
AnalizadaCrítica (9.8)0.68%—Dell Powerprotect DP Series ApplianceDell Data Domain Operating System22/4/202617/6/2026
Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain a stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access…
ModificadaMedia (6.7)0.13%—Dell Data Domain Operating System20/4/20264/8/2026
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability. A high privileged attacker with local access could…
AnalizadaMedia (6.7)0.19%—Dell Powerprotect DP Series ApplianceDell Data Domain Operating System20/4/202617/6/2026
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a stack-based buffer overflow vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to…
AnalizadaAlta (7.2)2.0%—Dell Powerprotect DP Series ApplianceDell Data Domain Operating System20/4/202617/6/2026
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to…
AnalizadaAlta (7.2)1.4%—Dell Powerprotect DP Series ApplianceDell Data Domain Operating System20/4/202617/6/2026
Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root…
AnalizadaAlta (7.2)1.2%—Dell Powerprotect DP Series ApplianceDell Data Domain Operating System20/4/202617/6/2026
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to…
Orbitaley — Vulnerabilidades